site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
775
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


antdude
A Ninja Ant
Premium,VIP
join:2001-03-25
United State
kudos:4
Reviews:
·RoadRunner Cable

Everything You've Been Told About Passwords Is Wrong

»www.wired.com/opinion/2012/10/pa···icality/ from »www.linuxsecurity.com/content/view/158224


norwegian
Premium
join:2005-02-15
Outback
Reviews:
·WestNet Broadband


This has almost been discussed until it is a worn out argument.

What will be the next layer for securing web access?

Thanks though for the reminder, a user cannot be told enough what passwords they use may ultimately break that lock on all of their privacy and worse case, funds they have saved over their life for retirement.
--
The only thing necessary for the triumph of evil is for good men to do nothing - Edmund Burke


Kearnstd
Elf Wizard
Premium
join:2002-01-22
Mullica Hill, NJ

1 edit

reply to antdude
I think RSA keys like the Blizzard Authenticator will be the big next step for more bank sites.

Also I would say that if someone lives alone, high complex passwords and a little black book of them is not a terrible idea. Because if someone gains access to the book they already have physical layer access to the computer and your home.

In general a secured password life gets harder as we have more passwords to remember. And in the office dwelling world one even has to deal with a bigger threat to security, the requirement to change passwords as short as every 30 days. Which usually leads to the old just adding a number.


dave
Premium,MVM
join:2000-05-04
not in ohio
kudos:8

Yes, that's exactly it - the problem of scale. Even using the article's advice of picking a phrase that's memorable to me(*), I still have to come up with a few dozen of them. Or some simple variation: but that leaves me open to "got one, figure out the rest" attacks.

(*) I offer as a suggestion "Y0urPassw0rdP0licySucks!" Except I'd use ruder words.



KodiacZiller
Premium
join:2008-09-04
73368
kudos:2

reply to antdude
Use a password manager.



Blackbird
Built for Speed
Premium
join:2005-01-14
Fort Wayne, IN
kudos:3
Reviews:
·Frontier Communi..

reply to antdude
I use Kearnstd See Profile's "little black book" technique, though in my case it's a few stapled sheets of paper instead of a little black book. For travel use, I keep a shorter version of it in my billfold. One added security trick I employ is to semi-encrypt the index titles with meanings that only I would know. For example:
sbmstp......9315-432 might be the full PIN for accessing my State Bank credit card
hmem1a......zz35_9a might be the access word for one of my Hotmail eMail accounts
ucbb2l......2trackball8 might be the log-in word for one of my Blackbird computers
wbbfli......er87dwx might be the log-in word for my Wilders forum Blackbird account
etc..

Because my index terms never really change over time, they become reflexively identifiable by me. The passwords do change frequently, so all I have to do is update the entries for the index terms and run a fresh version of my list... the master is kept robustly encrypted. The idea is to use only obscure, but personably-identifiable terms for the index terms. If a thief or stranger can't decipher what the index terms mean, there's no risk of the passwords being misused.
--
"Is life so dear, or peace so sweet, as to be purchased at the price of chains and slavery? Forbid it, Almighty God!" -- P.Henry, 1775



TopShelf

join:2010-06-25

reply to Kearnstd

said by Kearnstd:

...And in the office dwelling world one even has to deal with a bigger threat to security, the requirement to change passwords as short as every 30 days. Which usually leads to the old just adding a number.

Because I have a hard enough time remembering what day of the week it is let alone a password that has to change every 45 (in my office environment, anyway) days, I've defeated IT's mandatory directive on not re-using passwords increased by a unit of 1 within the last 45 days by having 5 easy to remember words/phrases/whatever and rotating them alphabetically and the number at the end does increase by 1.

For example:

Ankle01
Bone02
Comedy03
Dumbo04
Echo05

Ankle06
Bone07.....

You get the drift.

Simplicity....it works for me.
--
The only thing North Korea could wipe out in four minutes is a South Korean all-you-can-eat buffet.


mackey

join:2007-08-20
kudos:3

reply to antdude


/M



Juggernaut
Irreverent or irrelevant?
Premium
join:2006-09-05
Kelowna, BC
kudos:2

Hey! That's my PW!



Snowy
mIRC unix.ro UnderNet
Premium
join:2003-04-05
Kailua, HI
kudos:6
Reviews:
·RoadRunner Cable
·Clearwire Wireless

said by Juggernaut:

Hey! That's my PW!


I already knew that.


Juggernaut
Irreverent or irrelevant?
Premium
join:2006-09-05
Kelowna, BC
kudos:2

Yea, but you are the 'One'. It's ok.



sivran
Opera ex-pat
Premium
join:2003-09-15
Arlington, TX
kudos:1

reply to mackey
Now if only all systems accepted unlimited length passwords (not to mention spaces). I could easily expand some of my passwords that look like the first panel.. into passwords with much more entropy than the the one in the fourth...
--
Think Outside the Fox.



mackey

join:2007-08-20
kudos:3

Yeah, wtf is up with requiring a symbol but not allowing spaces??

/M



Blackbird
Built for Speed
Premium
join:2005-01-14
Fort Wayne, IN
kudos:3
Reviews:
·Frontier Communi..

said by mackey:

Yeah, wtf is up with requiring a symbol but not allowing spaces??

/M

Space characters have been alleged to cause inconvenience (and in many cases irreparable harm) to electrons in the Intertubes, as well as possibly causing cumulative damage to the space-time continuum. Since a 'space' is an empty place, using tangible, finite electrons to represent emptiness causes them untold confusion, resulting in reverse spin influences. Eventually, the electrons that are thus abused will slow down and stop... whereupon the space they are trying to represent fills up with dead electrons. Very, very bad...
--
"Is life so dear, or peace so sweet, as to be purchased at the price of chains and slavery? Forbid it, Almighty God!" -- P.Henry, 1775


Juggernaut
Irreverent or irrelevant?
Premium
join:2006-09-05
Kelowna, BC
kudos:2

Yea, and it causes a tear in the fabric of the Matrix, as well. Using the Force doesn't help.
--
I'm not anti-social, I just don't like stupid people.



Blackbird
Built for Speed
Premium
join:2005-01-14
Fort Wayne, IN
kudos:3
Reviews:
·Frontier Communi..

said by Juggernaut:

... Using the Force doesn't help.

That's because the Dark Side is made up of dead electrons, against which the Miticloreans must wage continual struggle.
--
"Is life so dear, or peace so sweet, as to be purchased at the price of chains and slavery? Forbid it, Almighty God!" -- P.Henry, 1775


Juggernaut
Irreverent or irrelevant?
Premium
join:2006-09-05
Kelowna, BC
kudos:2

Even Neutrinos are helpless. Master Yoda, where are you?
--
I'm not anti-social, I just don't like stupid people.


Tuesday, 18-Jun 04:22:13 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics